PDA

View Full Version : WARNING-PSN still not safe after system update -read post



blackwiggle
19th May 2011, 02:19 AM
I just saw this posted and have cut and pasted the original post :frown:
I suggest you repeatable visit the link below to the original post, as it has been update several times over the last few hours with information regarding the response from SONY when the poster told them about the exploit.

Apparently SONY has shut down the Web based PSN login / Password recovery function, it is now down for maintenance
.........................

Quote:
I want to make this clear to ALL PSN users. Despite the methods currently employed to force a password change when you first reconnect to the PlayStation network, your accounts still remain unsafe.
A new hack is currently doing the rounds in dark corners of the internet that allows the attacker the ability to change your password using only your account’s email and date of birth.

It has been proven to me through direct demonstration on a test account, so I am without any shadow of a doubt that this is real.

I would suggest that you secure your accounts now by creating a completely new email that you will not use ANYWHERE ELSE, and switching your PSN account to use this new email. You risk having your account stolen, when this hack becomes more public, if you do not make sure that your PSN account’s email is one that cannot be affiliated with or otherwise traced to you.

While we originally assumed this was a poor hoax designed only to stir the community into another frenzy, the individual who we are in contact with requested just two pieces of information from us: this being an account email and the date of birth used for that account. We promptly created a new account via us.playstation.com and provided the individual with the email address and date of birth used.

Roughly a minute later they requested that we try to login with the password we used for the account (which they did not know at any point), and sure enough, we were presented with an invalid username and/or password prompt.

In addition to this, within a few minutes we received an email from Sony stating the following:

This email confirms that your PlayStation(R)Network password account has been changed successfully.

If you did not change your password…
This email has been sent to you because the password for the relevant PlayStation(R)Network account has been changed.
If you did not change your password, please contact Customer Support at the following address:

networksupport@uk.playstation.com

The PlayStation(R)Network Team

While we will not reveal specific details regarding how the exploit is performed for obvious reasons, we can say that the exploit involves a vulnerability in the password reset form currently implemented, not properly verifying tokens.

http://sony.nyleveia.com/2011/05/17/warning-all-psn-users-your-accounts-are-still-not-safe/

MegaGeeza22
19th May 2011, 02:38 AM
I thought sony said it wasn't hacked an hour or 2 ago?
http://blog.eu.playstation.com/2011/05/18/update-on-psn-password-reset-process/

Cant you just change your date of birth lol, that would stop the hacks lol.
i have also changed my email password, no big deal really but i hope nobody gets hacked

blackwiggle
19th May 2011, 02:54 AM
No you can't change your date of birth, that information can only be entered in once when you first sent up a user account.
You can change your email address though, which is what I'm going to do, I've just started a Gmail account specifically for PSN use and will change the info on the console to that.

Changing your password will not protect you, well didn't with this last found exploit, all they needed was your email address and date of birth.

I figure since all that original personal info got stolen it's only a matter of time before some other exploit is found, better safe than sorry.

MegaGeeza22
19th May 2011, 03:08 AM
I agree, even though sony "claim" to have all these problems under control i believe these die hard hackers will never give up and eventually they will find a loophole somewhere.
So its best to change your details just to be on the safe side.
but i wont change my email just yet as i havent heard of anybody being hacked throughout these past few months because of sony... apart from the lies lol

DJ Techno
19th May 2011, 08:04 AM
thats funny tho

the psn is half online...

you can still talk to your friends and stuff. but not go to the stores and probably play against people online.

i read the same news on yahoo news. its nothing to worry about to me.
people said the network was going back up after may 30th. instead its back up in the middle of the month. so they rushed it. and falling back to catch what they missed.

MetaKraken
19th May 2011, 11:40 AM
Well, that's just great...

I tried changing my email back then, though it refused to accept it, so IDK if it would happen for me today...

EDIT: I'm unable to change my e-mail address on the PS3, so I might have the worst luck when hackers strike again...

BulletWraith
27th May 2011, 03:41 PM
thanks sony, I feel so reassured now :lol

(I kid you not, this is actually what I got when I went to change my password, almost fell out me chair)

zer:donutshen